Pentest de Infraestructura Interna (Gray Box)Internal Infrastructure Penetration Testing (Gray Box)
Ataque con credenciales estándar desde dentro de la red.Attack from inside the network using standard user credentials.
¿Qué es este servicio?What is this service?
Es una prueba desde dentro de la red, partiendo de las credenciales de un usuario estándar o de una toma de red. Es la caja gris: se simula qué puede lograr un empleado descontento o un atacante que ya entró por un phishing.
A test from inside the network, starting from a standard user's credentials or a network port. This is the grey box: it simulates what a disgruntled employee or an attacker who already got in through phishing could achieve.
¿Para qué se usa?What is it used for?
Sirve para medir qué tan lejos llega alguien una vez dentro. El escenario realista de hoy no es que nadie entre nunca, sino que alguien entre y no pueda hacer nada. El objetivo típico es la escalada hasta administrador de dominio, y el camino que se recorre para llegar ahí es el verdadero informe.
It measures how far someone gets once inside. Today's realistic scenario is not that nobody ever gets in, but that whoever gets in can do nothing. The typical objective is escalation to domain administrator, and the path taken to get there is the real report.
Qué beneficios traeBenefits it delivers
- Revela la falta de segmentación, que es el hallazgo más común y el que más caro sale de arreglar después.
- Muestra rutas de escalada de privilegios que ninguna herramienta automática encadena por sí sola.
- Pone a prueba la detección: si el equipo de seguridad no ve nada durante una semana de actividad, eso es un hallazgo mayor que cualquier vulnerabilidad.
- Cuantifica el daño real de un phishing exitoso, que es el vector de entrada dominante.
- Reveals the lack of segmentation, the most common finding and the most expensive to fix later.
- Shows privilege escalation paths that no automated tool chains together on its own.
- Tests detection: if the security team sees nothing during a week of activity, that is a bigger finding than any vulnerability.
- Quantifies the real damage of a successful phishing attack, the dominant entry vector.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal directa en Costa Rica.
- PCI-DSS lo exige por contrato a quien procese tarjetas, y aplica igual acá.
- Para entidades supervisadas, es la evidencia habitual del control de riesgo tecnológico del Acuerdo CONASSIF 5-24.
- There is no direct legal obligation in Costa Rica.
- PCI-DSS requires it contractually from card processors, and applies here just the same.
- For supervised entities, it is the usual evidence of the technology risk control under CONASSIF Agreement 5-24.
InternacionalInternational
- PCI-DSS lo exige en el requisito 11.4.2: pentest interno al menos cada doce meses y tras cambios significativos.
- Las pruebas de segmentación son obligatorias cada doce meses, y cada seis para proveedores de servicios.
- DORA y NIS2 exigen pruebas de seguridad periódicas a las entidades cubiertas.
- PCI-DSS requires it in requirement 11.4.2: internal penetration testing at least every twelve months and after significant changes.
- Segmentation testing is mandatory every twelve months, and every six for service providers.
- DORA and NIS2 require periodic security testing from covered entities.
Requisitos mínimosMinimum requirements
- Autorización por escrito y reglas de compromiso firmadas.
- Un punto de conexión a la red, físico o por VPN, y credenciales de un usuario sin privilegios.
- Definir si el equipo de seguridad está avisado o no; las dos opciones son válidas pero miden cosas distintas.
- Acordar qué ocurre si se encuentra un compromiso activo, porque en ese punto la prueba se detiene y comienza la respuesta a incidentes.
- Written authorisation and signed rules of engagement.
- A network connection point, physical or via VPN, and credentials for an unprivileged user.
- Deciding whether the security team is informed; both options are valid but measure different things.
- Agreeing what happens if an active compromise is found, since at that point testing stops and incident response starts.
Plazo típico de entregaTypical delivery time
El rango habitual del mercado va de dos a cuatro semanas, con entrega del informe entre una y dos semanas después del cierre. Una red plana de una sede se cubre en dos; un entorno con varios dominios y sedes se va a cinco o seis.
The usual market range runs from two to four weeks, with the report delivered one to two weeks after closing. A flat single-site network is covered in two; an environment with several domains and sites stretches to five or six.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.